Missing Authorization Vulnerability in Kibana by Elastic
CVE-2026-72664

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72664?

A missing authorization vulnerability in Kibana allows users with limited permissions to execute Elastic Defend response actions on managed hosts. Specifically, users authorized only for detection rule creation can improperly link automated response actions to these rules without possessing the required endpoint response action privileges. As a result, when alerts are triggered, these unauthorized response actions can be executed against the affected hosts, posing significant security risks.

Affected Version(s)

Kibana 8.9.0 <= 8.19.19

Kibana 9.0.0 <= 9.4.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.